Write-ups

Check The Published Writeups

WDBTitleTagsProgramsAuthorsTypePublicationAdded
1838How Docker Made Me More Capable and the Host Less Secure Local Privilege Escalation Microsoft Alon Zahavi (@Alon_Z4) Bug Bounty2022-02-082023-06-13
1773Skype extension: All functionality broken? Still exploitable! Information disclosure Privacy issue Microsoft Wladimir Palant (@WPalant) Bug Bounty2022-03-012023-06-13
1740How I bypassed disable_functions in php to get a remote shell RCE NA Asem Eleraky (@melotover) Bug Bounty2022-03-132023-06-13
1725How I was able to find 50+ Cross-site scripting (XSS) Security Vulnerabilities on Bugcrowd Public Program? XSS NA akshal(tojojo) Bug Bounty2022-03-162023-06-13
1713CVE-2022-0337 System environment variables leak on Google Chrome, Microsoft Edge and Opera Browser hacking Google Microsoft Opera Maciej Pulikowski (@pulik_io) Bug Bounty2022-03-192023-06-13
1692How I was able to rick roll every users on root-me.org XSS Root-Me Mizu (@kevin_mizu) Bug Bounty2022-03-272023-06-13
1675Debugging the undebuggable and finding a CVE in Microsoft Defender for Endpoint Endpoint spoofing Microsoft Gijs Hollestelle Bug Bounty2022-04-012023-06-13
1670How The Tables Have Turned: An analysis of two new Linux vulnerabilities in nf_tables Memory corruption Local Privilege Escalation Linux Kernel Organization David Bouman (@pqlqpql) Bug Bounty2022-04-022023-06-13
1668Exploiting a double-edged SSRF for server and client-side impact SSRF NA Yassine Aboukir (@Yassineaboukir) Bug Bounty2022-04-032023-06-13
1667Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline Privilege escalation CI/CD GitHub Noam Dotan Bug Bounty2022-04-042023-06-13
1638NotGitBleed Information disclosure GitHub Aaron Devaney Bug Bounty2022-04-112023-06-13
1618How I was able to see likes and dislikes count even though is hidden by victim | YouTube #4 Broken Access Control Google R ando (@Rando02355205) Bug Bounty2022-04-152023-06-13
1612Palisade identifies Wormable Cross-Site Scripting Vulnerability affecting Rarible’s NFT Marketplace XSS Rarible Palissade (@PalisadeLLC) Bug Bounty2022-04-182023-06-13
1610AWS%27s Log4Shell Hot Patch Vulnerable to Container Escape and Privilege Escalation Privilege escalation Container escape AWS Unit 42 (@Unit42_Intel) Bug Bounty2022-04-192023-06-13
1585Vulnerable GitHub Actions Workflows Part 2: Actions That Open the Door to CI/CD Pipeline Attacks Privilege escalation CI/CD NA Noam Dotan Bug Bounty2022-05-022023-06-13
1541How I was able to access IBM internal documents Information disclosure IDOR IBM Mohamed Taha (@Mohamed12742780) Bug Bounty2022-05-192023-06-13
1534How I was able to down a service of Microsoft ? Denial of Service (DOS) Attack on Microsoft. DoS Microsoft Harsh Banshpal (@harshbanshpal) Bug Bounty2022-05-212023-06-13
15202nd RCE and XSS in Apache Struts before 2.5.30 RCE Double OGNL evaluation XSS Apache Struts Chris (@mc_0wn) Bug Bounty2022-05-252023-06-13
1473How I was able to see likes and dislikes count which is hidden by victim | YouTube #1 Logic flaw Authorization flaw Google Jay Jani (@JayJani007) Bug Bounty2022-06-142023-06-13
1464Hertzbleed Attack Side-channel attack Hardware hacking Cryptographic issues Intel Cloudflare Microsoft Yingchen Wang (@YingchenWang96) Bug Bounty2022-06-142023-06-13
1455Chaining MFA-Enabled IAM Users with IAM Roles for Potential Privilege Escalation in AWS Privilege escalation AWS Jason Kao Bug Bounty2022-06-162023-06-13
1452How I was able to see likes and dislikes count which is hidden by victim | YouTube #2 Logic flaw Authorization flaw Google Jay Jani (@JayJani007) Bug Bounty2022-06-172023-06-13
1440We were vulnerable - how a security company could have vulns Broken Access Control Authorization flaw Information disclosure Volkis Soman Verma Bug Bounty2022-06-222023-06-13
1366Tableau Server Leaks Sensitive Information From Reflected XSS Reflected XSS Salesforce Simon Bouchard (@SimTwisted) Bug Bounty2022-07-142023-06-13
1346Authomize Discovers PassBleed Password Stealing and Impersonation Risks in Okta Sensitive data sent over an unencrypted channel Authorization flaw Information disclosure Okta Authomize (@Authomize) Bug Bounty2022-07-192023-06-13